MKDOOR is a modular Windows backdoor associated with China-aligned intrusion activity and observed in campaigns using the PeckBirdy JScript command-and-control framework. It is designed as a two-component system consisting of a downloader and a backdoor module. In observed operations, victims were lured through fake Google Chrome update pages delivered from compromised websites, after which the downloader retrieved and launched the backdoor component.
The downloader includes defense-evasion measures intended to reduce detection on infected hosts, including abuse of Microsoft Defender exclusions. MKDOOR also attempted to disguise command-and-control traffic as legitimate Microsoft-related web activity. Reporting further indicates behavioral overlap with BIOPASS RAT in its use of a localhost HTTP listener, suggesting support for local coordination with browser-based or watering-hole components.
MKDOOR was used in the SHADOW-VOID-044 campaign, which targeted the Chinese gambling sector through watering-hole compromises, and has been linked in that context to infrastructure and activity overlaps associated with UNC3569. The malware forms part of a broader modular toolset delivered alongside other backdoors such as HOLODONUT to support stealthy post-compromise access and cyber-espionage objectives. High-confidence reporting supports MKDOOR as a backdoor rather than merely a downloader, although its architecture includes a dedicated downloader stage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Delivered scripts observed include CVE-2020-16040 exploitation for Chrome, social engineering pop-ups, Electron JS backdoor delivery, and TCP reverse shell establishment.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After downloading and analyzing the file, we identified another modularly-designed backdoor, MKDOOR, which is composed of two different modules: the downloader and the backdoor.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The PeckBirdy server has defined APIs, which allows clients to obtain landing scripts from the server via a simple HTTP(S) query... If neither of these methods are supported, PeckBirdy can use the Comet and LocalComet methods, which are based on HTTP(S) and AJAX protocols.
To execute HOLODONUT, the threat actors deployed a customized simple downloader used to retrieve the payload from the remote server downloader that we tracked as NEXLOAD... During the first initiation, the downloader will connect to the C&C server and download the backdoor module.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular backdoor composed of a downloader and backdoor module. The downloader retrieves the backdoor from C2, attempts to evade Microsoft Defender by adding exclusions, disguises URLs as Microsoft support or Windows activation pages, and supports installing, uninstalling, executing modules, sleeping, status reporting, and exit.
Modular backdoor used with PeckBirdy in coordinated campaigns to provide persistent access and additional functionality.
Two-module backdoor (downloader + backdoor) that adds Microsoft Defender exclusions, disguises C2 as Microsoft support/Windows activation traffic, and supports module management commands (install/uninstall/execute/manage additional modules from C2).
An advanced modular backdoor delivered via PeckBirdy in a fake Chrome update/watering-hole style infection chain, used for persistent access and follow-on activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.